Skip to content

chore(deps): bump the go-dependencies group with 3 updates - #28

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-dependencies-404a9d5663
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-dependencies-404a9d5663

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the go-dependencies group with 3 updates: github.com/moby/buildkit, github.com/moby/moby/api and github.com/moby/moby/client.

Updates github.com/moby/buildkit from 0.33.0 to 0.33.1

Release notes

Sourced from github.com/moby/buildkit's releases.

v0.33.1

Welcome to the v0.33.1 release of buildkit!

Please try out the release binaries and report any issues at https://github.com/moby/buildkit/issues.

Contributors

  • Tõnis Tiigi
  • CrazyMax
  • Sebastiaan van Stijn

Notable Changes

  • Built-in Dockerfile frontend has been updated to v1.27.1 changelog.
  • Fix proxy CA cleanup so build steps cannot redirect it outside the build rootfs, block it with a special file, or succeed when cleanup fails. GHSA-2f5p-x9ph-g97x
  • Fix a daemon panic when a build requests CDI devices while CDI support is disabled. Optional devices are ignored; required devices produce an error. GHSA-r456-g3gm-cvxf
  • Verify container blob contents against their claimed digest before caching them. This protects shared caches from unverified blobs supplied through the low-level LLB API. GHSA-p3rc-w3hc-pqvv
  • Verify applied image layer DiffIDs, bind lazy stargz snapshots to their verified TOC digest, and isolate legacy layer snapshots. Image source cache keys no longer rely on unverified DiffIDs. GHSA-f2v9-hprr-32q3
  • Prevent malicious external frontends from crashing the daemon through gateway container lifecycle races or malformed requests and definitions. GHSA-4hgw-qrhw-fhg8
  • Reject special files in daemon-side snapshot reads and replace existing special files safely in LLB mkfile operations. GHSA-9728-qjrv-2xh2
  • Reject malformed LLB file operations with invalid symlink owner inputs instead of allowing a daemon panic. GHSA-fjj4-h6vf-m9hj
  • Reject malformed LLB merge operations with mismatched input counts instead of allowing a daemon panic. GHSA-cv6p-7w7g-xjwq
  • Limit Dockerfile, .dockerignore, gateway file, and nested LLB definition reads to prevent oversized inputs from exhausting daemon memory. GHSA-mgqf-486f-49vp
  • Apply source policies to Git bundle locators and reject Git full remote URLs that do not match the source identifier. GHSA-66hf-6vf5-87hc

Dependency Changes

  • github.com/containerd/containerd/v2 v2.3.4 -> v2.3.6
  • golang.org/x/crypto v0.55.0 -> v0.56.0

Previous release can be found at v0.33.0

Commits
  • 8c91502 Merge pull request #7230 from crazy-max/v0.33_picks_v0.33.1
  • a9d42a8 vendor: github.com/containerd/containerd/v2 v2.3.6
  • 9d198b8 vendor: github.com/containerd/containerd/v2 v2.3.5
  • 98f8583 vendor: golang.org/x/crypto v0.56.0
  • adc9d52 client: preserve the caller context for local cache reset
  • e7379bc sourcepolicy: evaluate Git bundle sources
  • 86ea38d vendor: gomod regen
  • dbf9012 security: validate Git full remote URLs
  • d26401f security: limit daemon file reads
  • 7d1ec17 dockerfile: limit epoch archive reads
  • Additional commits viewable in compare view

Updates github.com/moby/moby/api from 1.56.0 to 1.56.1

Release notes

Sourced from github.com/moby/moby/api's releases.

api/v1.56.1

1.56.1

Changelog

Commits
  • 14ebc60 Merge pull request #53830 from tonistiigi/update-buildkit-v0.34.0-rc1
  • 8eded0e Merge pull request #53671 from thaJeztah/add_WithHTTPRequestHook
  • c4e39af Merge pull request #53596 from vvoland/c8d-refactor-imgload
  • b8a569e client: add WithHTTPRequestHook option
  • 0fed273 Merge pull request #53803 from thaJeztah/etchosts_cleanups
  • 80c72a3 Merge pull request #53831 from corhere/fix-dnsproxy-servfail-test
  • 1cfa161 daemon/containerd: Split image loading into import and unpack steps
  • e7272aa Merge pull request #53606 from flostellbrink/fix/swagger-yaml-indentation
  • 357096e libnetwork/etchosts: keep file open when updating hosts
  • 012b2ef libnetwork/etchosts: propagate file close errors
  • Additional commits viewable in compare view

Updates github.com/moby/moby/client from 0.6.0 to 0.6.1

Release notes

Sourced from github.com/moby/moby/client's releases.

client/v0.6.1

0.6.1

Changelog

Changelog

Sourced from github.com/moby/moby/client's changelog.

0.6.1 (2013-08-23)

  • Registry: Pass "meta" headers in API calls to the registry
  • Packaging: Use correct upstart script with new build tool
  • Packaging: Use libffi-dev, don't build it from sources
  • Packaging: Removed duplicate mercurial install command
Commits
  • 5105263 Bump to v0.6.1
  • 7b5c579 Use correct upstart script with new build tool
  • 15d658d Removed duplicate mercurial install command
  • 59281d6 use libffi-dev, don't build it from sources
  • 29be20f Fixed: ImagePull in runtime test
  • 5a8c32d Use additional decorator in RequestFactory to pass meta headers to registry
  • 588f8e1 Merge pull request #1628 from dotcloud/bump_0.6.0
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Bumps the go-dependencies group with 3 updates: [github.com/moby/buildkit](https://github.com/moby/buildkit), [github.com/moby/moby/api](https://github.com/moby/moby) and [github.com/moby/moby/client](https://github.com/moby/moby).


Updates `github.com/moby/buildkit` from 0.33.0 to 0.33.1
- [Release notes](https://github.com/moby/buildkit/releases)
- [Commits](moby/buildkit@v0.33.0...v0.33.1)

Updates `github.com/moby/moby/api` from 1.56.0 to 1.56.1
- [Release notes](https://github.com/moby/moby/releases)
- [Commits](moby/moby@api/v1.56.0...api/v1.56.1)

Updates `github.com/moby/moby/client` from 0.6.0 to 0.6.1
- [Release notes](https://github.com/moby/moby/releases)
- [Changelog](https://github.com/moby/moby/blob/v0.6.1/CHANGELOG.md)
- [Commits](moby/moby@v0.6.0...v0.6.1)

---
updated-dependencies:
- dependency-name: github.com/moby/buildkit
  dependency-version: 0.33.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/moby/moby/api
  dependency-version: 1.56.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/moby/moby/client
  dependency-version: 0.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants